• I have recently uninstalled iThemes Security on two WooCommerce websites since it blocked all callbacks from the payment gateway and logistic partner. The problem started when I activated iThemes Security and disappeared immediately after deactivating the plugin.

    The payment gateway (Bambora) and logistics partner could receive data (orders) from the WooCommerce website, but when they tried sending back the updated order status, they only got 403 error messages. No callbacks was allowed.

    I tried changing the following settings in iThemes Security but it didn’t help:

    * Adding all IP numbers used by the payment gateway and logistics partner to Lockout White List
    * Changing the WordPress API settings from “Restricted Access” to Default Access
    * Disabling Away Mode

    Any ideas on what iThemes Security setting that can cause the 403 error messages?

Viewing 2 replies - 1 through 2 (of 2 total)
  • If enabled try and disable the Default Blacklist setting in the Banned Users module.

    Try this first. If it still doesn’t work there is another module that may cause troubles…

    To prevent any confusion, I’m not iThemes.

    Hi Victor,

    Disabling the Default Blacklist is a great first step. If that does not resolve the issue you can try disabling the following one at a time to see which is the culprit.

    Filter Long URL Strings
    (Security> Settings> System Tweaks)

    Filter Suspicious Query Strings in the URL
    (Security> Settings> System Tweaks)

    Filter Non-English Characters
    (Security> Settings> System Tweaks)

    You may also try enabling XML-RPC and allowing Full Access to the REST API.
    (Security> Settings> WordPress Tweaks> XML-RPC)

    Thanks,

    Matt

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘403 error for WooCommerce callbacks’ is closed to new replies.